CVE-2025-5520

Source
https://cve.org/CVERecord?id=CVE-2025-5520
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5520.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-5520
Published
2025-06-03T18:15:27.257Z
Modified
2026-04-12T17:14:07.659900Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmmstateauthentication/emmstateauthentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.

References

Affected packages

Git / github.com/open5gs/open5gs

Affected ranges

Type
GIT
Repo
https://github.com/open5gs/open5gs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.1.0
v0.1.1
v0.2.0
v0.3.0
v0.3.1
v0.3.10
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.8
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.5.0
v0.5.1
v0.5.2
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
v2.*
v2.0.0
v2.0.18
v2.0.22
v2.1.0
v2.1.1
v2.1.3
v2.1.4
v2.1.5
v2.1.7
v2.2.0
v2.2.1
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.2
v2.3.6
v2.4.0
v2.4.1
v2.4.3
v2.4.4
v2.4.5
v2.4.7
v2.4.8
v2.4.9
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.6
v2.7.0
v2.7.1
v2.7.2
v2.7.5

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/amf/gmm-sm.c",
            "function": "gmm_state_security_mode"
        },
        "id": "CVE-2025-5520-0ef524c2",
        "deprecated": false,
        "digest": {
            "function_hash": "83500632070580911998797047966065524410",
            "length": 8423.0
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/amf/gmm-sm.c",
            "function": "gmm_state_exception"
        },
        "id": "CVE-2025-5520-3a05cf93",
        "deprecated": false,
        "digest": {
            "function_hash": "160781599133266726046446224547111322076",
            "length": 7169.0
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/mme/emm-sm.c",
            "function": "emm_state_authentication"
        },
        "id": "CVE-2025-5520-6869893c",
        "deprecated": false,
        "digest": {
            "function_hash": "22859958192396035505212974093563823443",
            "length": 4124.0
        }
    },
    {
        "signature_type": "Line",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/amf/gmm-sm.c"
        },
        "id": "CVE-2025-5520-7cf36230",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "162612948853236519870417624286336986397",
                "279800737103072097352342639440643898857",
                "224344108714082424795084970797513107060",
                "92174190948770943019300478285797406489",
                "11496801759268304833503557185898646113",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "256210522018344380583522769866622864221",
                "8531826659309212253945361217639555917",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "256210522018344380583522769866622864221",
                "88933678767554333444634080757504132882",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "98279082891080693496667047401417186958",
                "218423668681304689602073986062147818177",
                "279800737103072097352342639440643898857",
                "63600953943289955141616430274593087484",
                "98279082891080693496667047401417186958",
                "218423668681304689602073986062147818177",
                "287361486533403811949021440182620113055",
                "329928212348722115459337753229020731516",
                "221167672963450854736231568572233024945",
                "171710928360583683359703307818570784637"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/mme/emm-sm.c",
            "function": "emm_state_exception"
        },
        "id": "CVE-2025-5520-8258339c",
        "deprecated": false,
        "digest": {
            "function_hash": "7840338246266733304109947859179352179",
            "length": 2198.0
        }
    },
    {
        "signature_type": "Line",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/mme/emm-sm.c"
        },
        "id": "CVE-2025-5520-888aab85",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "181587525657022427075386250389554607630",
                "214597673683049392675310664109267682895",
                "44783538911283254919575295468980251765",
                "17076408781526451615758545393702765642",
                "181587525657022427075386250389554607630",
                "252775408427670992673771619141331972551",
                "258020227633328548922632536403702770528",
                "133599961499748681934399517810130714389",
                "181587525657022427075386250389554607630",
                "193216346956972609628193931368582367486",
                "210300223049496830621915461069147382003",
                "14486022831773130212852169467389047262",
                "181587525657022427075386250389554607630",
                "53677434448106881679034576068327455465",
                "22640183906031040781591380454654267857",
                "135300274118787480034969130986824843604"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/amf/gmm-sm.c",
            "function": "common_register_state"
        },
        "id": "CVE-2025-5520-ad2585fe",
        "deprecated": false,
        "digest": {
            "function_hash": "116882255355674317971163153045468861679",
            "length": 9739.0
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/mme/emm-sm.c",
            "function": "emm_state_security_mode"
        },
        "id": "CVE-2025-5520-b03c51d3",
        "deprecated": false,
        "digest": {
            "function_hash": "72387096183728905946385029289657893898",
            "length": 5578.0
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/amf/gmm-sm.c",
            "function": "gmm_state_initial_context_setup"
        },
        "id": "CVE-2025-5520-d911ed6c",
        "deprecated": false,
        "digest": {
            "function_hash": "58969063080390576501044478447730453268",
            "length": 8629.0
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/amf/gmm-sm.c",
            "function": "gmm_state_authentication"
        },
        "id": "CVE-2025-5520-f9f3436d",
        "deprecated": false,
        "digest": {
            "function_hash": "126460456160147151523067791108123358265",
            "length": 8606.0
        }
    },
    {
        "signature_type": "Function",
        "source": "https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884",
        "signature_version": "v1",
        "target": {
            "file": "src/mme/emm-sm.c",
            "function": "emm_state_initial_context_setup"
        },
        "id": "CVE-2025-5520-fc955644",
        "deprecated": false,
        "digest": {
            "function_hash": "59366305747887547644834116805621754724",
            "length": 5436.0
        }
    }
]
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "2.7.0"
            },
            {
                "last_affected": "2.7.3"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5520.json"
vanir_signatures_modified
"2026-04-12T17:14:07Z"